The WP Front User Submit / Front Editor plugin on WordPress can be attacked by hackers in versions up to 4.9.3. This is because the plugin does not properly clean up user input and output. This allows attackers with administrator-level access to add harmful code to pages that will run when someone views the page. This only affects websites with multiple pages and websites that have disabled unfiltered_html.